Skip to main content Skip to navigation
Washington State University
Information Technology Services

Installing GlobalProtect VPN – Mac/Linux

Starting in September, ITS will be adding Multi-factor Authentication (MFA) to its general VPN portals. This will change the way that users log in to the VPN. Here is what to expect when the change occurs.

Mac GlobalProtect Client Install

On the Mac, The latest client is available from the VPN portal. Use https with a web browser to connect to https://vpn.wsu.edu.

  • Login with WSU AD credentials
  • No need for additional prefixes or suffixes
  • Example: john.smith@wsu.edu will only need username john.smith

Paloalto Login Screen

  • After logging in, download the Mac OS agent.

Paloalto Global Protect Portal

  • When prompted, run the software.
  • When prompted again, run the GlobalProtect Installer.

GlobalProtect Installer

  • From the GlobalProtect Installer, click continue.
  • On the destination select screen, select the install folder and then click continue.

GlobalProtect destination select

  • On the Installation Type screen, select the GlobalProtect installation package check box, and then click continue.
  • Click install to confirm that you want to install GlobalProtect.
  • When prompted, enter your Username and Password, and then click install software to begin the installation.
  • When this security box appears, users MUST click the “Open Security Preferences” Button (NOT the OK Button).

System Extension Blocked Pop-up

  • Click the “Allow” button at the bottom of the “Security & Privacy” box to allow the Palo Alto Extension.

Security and privacy window

  • After installation is complete, close the installer.

MFA GlobalProtect VPN Login Steps

Once the VPN portal has been updated to require MFA the user experience will change. When the user connects to the VPN, they will instead receive an Okta login page.

global protect sign in

global protect network authentication

On this page, enter your username and password. If you scroll down on this page, you will see a ‘Remember me’ option. Check this option to have your username saved for future logins. This is recommended.

global protect remember me checkbox

Once a valid credential pair is entered, you will receive a prompt to choose your MFA option. You can use any MFA option that is supported by Okta, including SMS, App Push, Google Authenticator, Security Key, etc. Push notifications with the Okta Verify App are recommended.

okta verify notification  browser window

choose okta verify sms google authenticator

When selecting Okta Verify Push notifications, it is recommended to select the option ‘Send push automatically’

okta verify send push automatically check box

While the option ‘Do not challenge me on this device for the next 24 hours’ option may be checked, this option will not have any effect. You will continue to be prompted for multi-factor authentication for every VPN login.

At this point, you should receive a multifactor prompt on your device or be ready to enter a code from a separate multi-factor app.
IOS Prompt

did you just try to sign in okta screen

did you just try to sign in okta screen

OKTA MFA Factor Enrollment
To set up your Okta MFA options, visit https://account.wsu.edu.

For technical assistance: Please contact Crimson Service Desk via email, by phone at (509) 335-4357, or online.

Mac Uninstall

Download the installer from the portal page at https://vpn.wsu.edu (same process as the previous Mac GP Client install).
From the GlobalProtect installer, click continue.

GlobalProtect Installer

On the destination select screen, click continue.
On the Installation Type screen, select the Uninstall GlobalProtect package check box, and then click continue:

GlobalProtect Uninstall Screen

Click Install to confirm that you want to remove the GlobalProtect app.
When prompted, enter your Username and Password, and then click Install Software to uninstall GlobalProtect.

GlobalProtect Uninstall Screen

A message will pop up that will confirm that the Uninstall GlobalProtect package was successfully installed and that the GlobalProtect app has been removed from the computer.

Linux Install

On Linux, the latest GlobalProtect client can be downloaded from:
There are two clients – download the rpm file for RedHat/CentOS.
For Ubuntu, download the deb file. Open a terminal window to install the client

Ubuntu/Debian –
sudo dpkg – i GlobalProtect_deb-5.0.8.deb

Redhat/CentOS –
sudo yum localinstall GlobalProtect_rpm-5.0.8.rpm

Linux Operation

Using a terminal window, type globalprotect. At the >> prompt, use the connect command to connect to portal vpn.wsu.edu.

user@ubuntu:~$ globalprotect
Current GlobalProtect status: OnDemand mode.
>> connect –portal vpn.wsu.edu
Retrieving configuration…
vpn.wsu.edu – Authentication Failed. Enter login credentials
username(user):user
Password:
Discovering network…
Connecting…
Connected

Other commands of note at the >> prompt include –
>> quit
(exits out of GlobalProtect which continues to run in the background)
>> disconnect
>> show –version
>> show –status
>> show –details

Linux Uninstall

  1. Uninstall the GlobalProtect app for Linux using dpkg.
  2. user@ubuntu:~$ sudo dpkg -P globalprotect
    (Reading database … 209181 files and directories currently installed.)
    Removing globalprotect (5.0.8) …
    gp service is running and we need to stop it…
    Disable service…
    Removing gp service…
    gp service has been removed successfully
    Removing configuration…

  3. Uninstall the GlobalProtect app for Linux using apt-get.
  4. user@linuxhost:~$ sudo apt-get remove GlobalProtect_deb-5.0.8.deb
    Reading package lists… Done
    Building dependency tree
    Reading state information… Done

Troubleshooting

7.1.1. Mac

    Open GlobalProtect and click on the Troubleshooting tab. An option to collect logs will create a support file that can be used for analysis.

    GlobalProject Troubleshooting

7.1.2. Linux
Using the terminal window and in globalprotect mode, run the collect-log command to create the support file.

user@ubuntu:~$ globalprotect
Current GlobalProtect status: Connected
>>
>> collect-log
Start collecting…
collecting network info…
collecting machine info…
copying files…
generating final result file…
The support file is saved to /home/user/.GlobalProtect/Collect.tgz